Shadowed · Shadowed Portal · CVE-2006-4826
**Name of the Vulnerable Software and Affected Versions**
Shadowed Portal versions 5.599 and earlier
**Description**
The issue allows remote attackers to execute arbitrary PHP code via a URL in the `root` parameter. This is a result of a PHP remote file inclusion vulnerability in the bottom.php file.
**Recommendations**
For Shadowed Portal versions 5.599 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.